A Survey of Quantitative Security Risk Analysis Models for Computer Systems

Ines Meriah, Latifa Ben Arfa Rabai · 2018

Security risk analysis is an essential part of the management of information systems. Models of security risk analysis have the same target to prevent risks caused by information assets, their potential threats, and vulnerabilities, in addition to security controls. Most of these models are used nowadays to quantify risk value without identifying the security problems of the organization. Thus, decisions-makers cannot make the correct decision to select the appropriate methodology for resolving security risks. In this context, a survey of quantitative security risk analysis models for computer systems is presented. We describe the models, their aims, their phases and the different stages of risk management addressed and security metrics. The goal is to give a set of recommendations for choosing the appropriate quantitative model related to security problems faced by organizations today.

Read the paper · More papers on PaperTik